CybersecurityJobs.io
← Back to all jobs

Job Description

Listen Labs is building an AI-native product where security is designed into the system from the start. As a Member of Technical Staff in Application Security, you will partner with engineers to protect sensitive data, strengthen multi-tenant isolation, and deliver secure-by-default engineering patterns across APIs, tooling, and deployment pipelines.

What You’ll Do

Focus on practical application security that ships with the product. You will help shape the protections data needs, validate trust boundaries, and close issues by building guardrails, libraries, and pipeline checks that reduce the chance of vulnerabilities reaching production.

  • Design product-integrated protections for sensitive data, including encryption, access boundaries, retention, and abuse resistance.
  • Ensure tenant, role, and study boundaries hold up under real conditions, and identify gaps before they become exploitable.
  • Threat-model AI-relevant failure cases such as prompt injection, data exfiltration through model outputs, tool and agent permissions, and new trust-boundary failure modes introduced by LLMs.
  • Build correct authentication and authorization flows and secure API surfaces for both programmatic callers and agentic callers in early versions.
  • Create secure-by-default libraries and patterns, and wire SAST, DAST, SCA, and secrets scanning into CI for faster feedback and safer releases.
  • Review architecture and pull requests with engineers who wrote the changes, and often implement fixes directly.

Technologies

  • TypeScript
  • Terraform
  • OAuth
  • OIDC
  • RBAC
  • SAST
  • DAST
  • SCA

Requirements

  • Strong engineering foundation: comfortable in a modern backend stack (Listen Labs uses TypeScript and Terraform), able to read and write production code, and hold your own in code reviews.
  • Junior-level or better development skills, with an engineering mindset prioritized over any single language.
  • Working knowledge of the OWASP Top 10 as failure patterns driven by real design decisions.
  • Ability to explain how authorization bugs occur, not just that they exist.
  • Comfort thinking in trust boundaries, threat models, and blast radius.
  • Experience focused on shipping fixes rather than writing tickets or delivering reports; close the loop by implementing guardrails, libraries, pipeline checks, or patches.
  • Depth in application security fundamentals, including authentication and authorization (OAuth/OIDC, sessions, RBAC), cloud and infrastructure security basics, secrets management, secure API design, and common vulnerability classes across web and backend systems.
  • Interest in learning how LLM systems fail; prior LLM security experience is a plus.
  • Root-cause orientation when something breaks.
  • Clear written communication to advocate for tradeoffs, explain risk to engineers, and get priorities aligned.
  • End-to-end problem solving: scope your work, consider customer trust, and own the decisions you make.

Location and Compensation

  • Location: New York, NY (onsite)
  • Salary: USD 180,000 - 300,000 per year

Benefits

  • Full medical, dental, and vision coverage (FSA/HSA and life insurance are available too).
  • Meaningful equity ownership. Range for this role is $180,000 – $300,000 base, with actual compensation influenced by skill set, experience, and work location.
  • Annual Learning Stipend for books, courses, conferences, coaching, language lessons, and related development activities.
  • Annual Wellness Stipend for gym memberships, race fees, massages, ergonomic gear, and more.
  • Monthly Stipend for AI tools, including software and GPU credits.
  • Fed, daily: a private chef serves lunch and dinner in the SF office; NYC and London teams receive daily meal credit.
  • Flexible time off with a take-what-you-need vacation policy.
  • Company offsites and events, including an annual holiday party.
  • Room to grow: as an early member of the team, you will own end-to-end processes from scratch and expand them alongside the company.

What You’ll Work On

  • Securing the Database of Humanity
  • Multi-Tenant Isolation
  • AI-Native Attack Surface
  • Securing the Human API
  • Security Engineering Platform
  • Design and Code Review

Similar Jobs